Build, Brand & Sell Digital Products
--:--:-- --
PRIVACY POLICY

How ClassWaze handles your data.

This Privacy Policy explains how ClassWaze collects, uses, protects and manages information in connection with our website, customer accounts, digital products and related services.

Effective: 14 September 2026 Last updated: 14 September 2026 Version: v1.3 India-focused notice
Important: This notice is intended to describe the privacy practices relevant to the services actually provided by ClassWaze. It should be read together with any just-in-time notice, consent mechanism, order/subscription terms and other privacy information presented when personal data is collected. The applicable legal requirements can change over time, so this policy is intended to operate subject to the law in force for the relevant processing activity.

01Overview

ClassWaze (“ClassWaze”, “we”, “us” or “our”) respects privacy and aims to handle personal data responsibly. This policy applies to personal data processed through our public website, customer accounts, onboarding, digital product and subscription workflows, support channels, reviews and related services.

Where a particular feature provides a separate privacy notice or asks for a specific consent, that notice may provide additional information for that processing activity.

02Data we collect

CategoryExamplesTypical source
Account & profileName, email, mobile number, login/account details and profile information you provide.Directly from you.
Business & onboardingBusiness details, website/branding information, onboarding details and verification information where required.You or an authorised representative.
Service activityPlan selection, product activity, purchases, downloads, reviews, support requests and related account activity.From your use of the services.
Transaction informationOrder/reference details, payment status, renewal/refund records and accounting information. Payment credentials may be handled directly by the payment provider.You and relevant service providers.
Technical & securityIP address, browser/device information, logs, approximate usage information, session information and security events.Website and security technologies.
Communication dataMessages, enquiries, feedback, reviews and information submitted through support/contact channels.Directly from you.

We seek to collect data that is reasonably relevant to the applicable purpose. Please avoid submitting unnecessary sensitive information, passwords, OTPs, UPI PINs, CVV values or other authentication secrets through ordinary website forms or support messages.

03How we use personal data

Depending on the service or interaction, personal data may be processed to:

  • create, authenticate and manage accounts and authorised access;
  • provide websites, digital products, subscriptions, purchases and related services;
  • complete, reconcile and document transactions and subscription activity;
  • perform onboarding, account verification and fraud/risk checks where reasonably required;
  • respond to support, privacy, refund, account or service requests;
  • maintain website functionality, reliability, performance and security;
  • detect, prevent and investigate fraud, misuse, unauthorised access or unlawful activity;
  • send service-related communications and, where legally permitted, promotional communications;
  • comply with applicable legal, tax, accounting, regulatory or lawful-authority requirements; and
  • improve services using information in a manner permitted by applicable law.

05Cookies & similar technologies

We may use cookies, session storage, local storage, logs, pixels or similar technologies for essential functionality, account sessions, preferences, security, analytics and service measurement where applicable.

Where non-essential technologies require consent under applicable law, an appropriate choice mechanism may be provided. Browser settings may also allow cookies or storage to be restricted or deleted, although doing so can affect certain features.

06Sharing & service providers

We do not sell personal data as a product. We may disclose or make personal data available where reasonably necessary for the purposes described in this policy, including to:

  • hosting, cloud, infrastructure and technology providers;
  • payment gateways and transaction service providers;
  • email, SMS, notification and customer-support providers;
  • analytics, security and fraud-prevention providers where used;
  • professional advisers, auditors or service providers where reasonably required;
  • government authorities, courts, regulators or law-enforcement bodies where legally required or permitted; and
  • a lawful successor entity in connection with a merger, restructuring, acquisition or transfer of business, subject to applicable law.

Where a third party processes personal data on our behalf, we seek appropriate contractual, technical and organisational safeguards consistent with applicable requirements.

07Payments & financial information

Paid services may use an external payment gateway or financial service provider. Such providers may process payment credentials directly under their own privacy terms and security controls.

We may retain transaction identifiers, order information, payment status, renewal/refund records and accounting information needed to provide the service, resolve disputes and meet legal or accounting obligations.

Payment credentialsPayment providers may handle sensitive payment credentials directly.
Transaction recordsWe may retain order, reference, status and refund information needed for service and records.
Security secretsWe do not intentionally request card CVV, UPI PIN, banking passwords or similar secrets through ordinary forms.

08Retention, deletion & account closure

We retain personal data only for as long as reasonably necessary for the relevant purpose, to provide services, maintain security, resolve disputes, enforce agreements, or comply with applicable legal, tax, accounting or regulatory obligations.

Closing an account does not necessarily result in immediate deletion of every record. Certain transaction, security, audit or legally required records may need to be retained for the applicable period.

Subscription expiryWhen a paid subscription reaches its end date, service access becomes inactive and a configured renewal grace period begins.
Domain releaseIf the subscription is not renewed within the grace period, the connected domain may be automatically released. The original domain is not guaranteed to remain available after release.
Retention windowAfter the domain-release milestone, customer account data is normally retained for the configured retention period, currently 90 days by default, before deletion eligibility is reached.

During the retention window, customer data may remain stored so that the account can be reviewed, legitimate service or support matters can be resolved, and any permitted renewal or recovery process can be considered. Renewal after a domain has been released does not guarantee restoration of the same domain.

When the retention period expires, the account may become Deletion Eligible. Permanent deletion is not automatic: an authorised platform administrator must review the account, confirm the applicable policy conditions, and explicitly approve the permanent deletion action. Once approved and completed, eligible tenant data and associated operational records/files are permanently removed, subject to any data that must lawfully be retained.

Where data is no longer required and no lawful retention ground applies, we will take reasonable steps to delete or anonymise it in accordance with our retention practices.

09Data security

We use reasonable technical and organisational safeguards appropriate to the nature of personal data and the risks involved. Depending on the system, safeguards may include:

  • access controls and restricted administrative access;
  • password protection and authentication controls;
  • encryption or other appropriate protection for data in transit or at rest where appropriate;
  • logging, monitoring and review of relevant access and security events;
  • backups and recovery measures;
  • security updates and vulnerability management; and
  • contractual and organisational controls for relevant service providers.

No internet transmission or storage system can be guaranteed to be completely secure. We therefore do not promise absolute security, but we work to reduce foreseeable risks and respond to product security incidents appropriately.

10Personal data incidents

If we become aware of a personal data breach or other product security incident involving personal data, we will assess and respond in accordance with applicable law. Where notification is required, we will provide the relevant information to affected individuals and/or notify the competent authority through the prescribed process and within applicable timelines.

Our response may include containment, investigation, remediation, access protection, restoration measures and steps intended to reduce the risk of recurrence.

11Your privacy rights

Subject to applicable law and any prescribed conditions, individuals may have rights relating to their personal data, which can include:

  • access to information about personal data being processed;
  • correction or completion of inaccurate or incomplete personal data;
  • erasure where the applicable legal conditions are met;
  • withdrawal of consent where processing is based on consent;
  • grievance redressal; and
  • other rights that may apply under the law in force for the relevant processing activity.

How to make a request

Use the official Contact Us channel published on the website. Please identify the account or information involved and clearly state the request. We may take reasonable steps to verify identity before acting on a request involving personal data.

Requests will be handled through the process and within the timelines prescribed by applicable law. Some requests may be limited where retention or processing is legally required or another lawful ground applies.

12Children's personal data

We take children's privacy seriously. Where Indian data-protection law applies, the definition of a child and the requirements for processing a child's personal data are determined by that law.

Where applicable law requires verifiable parental consent or other safeguards before processing a child's personal data, we will apply the required measures to the extent applicable to our processing activity.

We do not knowingly seek unnecessary personal information from children. If you believe a child has provided personal data to us in a manner that should not have occurred, please contact us.

13Customer-managed data & SaaS use

ClassWaze may provide software and account features that allow a customer or authorised organisation to publish digital products, manage customers, operate a branded website and maintain business records. Data entered by that customer through those features may be controlled by the customer and may include information about the customer's own users or customers.

Where applicable law treats the customer as the party deciding why and how that data is processed, the customer is responsible for having an appropriate privacy notice, lawful basis, permissions and user-facing practices for its own data collection and use. ClassWaze may process such information to provide, secure, maintain and support the requested service, subject to the customer's configuration, applicable agreements and applicable law.

Customers should not use ClassWaze to collect or upload personal data that is unnecessary for their stated business purpose, or information they are not legally permitted to collect or use.

14Data location & cross-border processing

ClassWaze may use hosting, cloud, payment, communications, analytics, security or other technology providers whose infrastructure or personnel may be located in India or another jurisdiction. The location used for a particular processing activity can depend on the service provider and technical architecture in use at that time.

Where personal data is transferred, accessed or processed across jurisdictions, we will apply the safeguards, contractual requirements, transfer restrictions and other measures required by applicable law for the relevant processing activity.

Customers using ClassWaze for their own users or customers remain responsible for considering any location, transfer or disclosure requirements that apply to their own data and business.

15Third-party websites & services

The website may contain links to third-party websites, payment pages, domain/hosting services, cloud resources or other integrations. Those third parties may maintain separate privacy policies and terms.

We are not responsible for independent third-party privacy practices outside our reasonable control. Review the applicable third-party notice before submitting personal data directly to that provider.

16Changes to this Privacy Policy

We may update this Privacy Policy when our services, technology, vendors, legal requirements or data practices change. The updated version will be published on this page with a revised “Last Updated” date and, where appropriate, a revised policy version.

If a change materially affects processing and applicable law requires additional notice or consent, we will provide the required notice or obtain the required consent.

17Grievance redressal & contact

For privacy questions, access/correction/deletion requests, complaints or other privacy concerns, please contact ClassWaze through the official Contact Us channel. We will maintain an appropriate grievance process and respond in accordance with applicable law.

Organisation ClassWaze Education Private Limited
Service / business ClassWaze · Platform Control Center